EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Ransomware

Known Indicators of Compromise Associated with Androxgh0st Malware

Fonte ufficiale
Sintesi operativa EudorIA

Cosa significa

Priorità 95/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Known Indicators of Compromise Associated with Androxgh0st Malware. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.

Perché conta

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Benefici operativi potenziali

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indicazioni da confermare sul perimetro tecnico e organizzativo del cliente.
Controlli pertinentiVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
DestinatariITSOCCISOManagement
Centro informazioni

Traduzione in elaborazione

CISA

Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.

Testo acquisito dalla fonte

Cybersecurity Advisory Known Indicators of Compromise Associated with Androxgh0st Malware Release Date January 16, 2024 Alert Code AA24-016A Related topics: Cyber Threats and Response , Malware, Phishing, and Ransomware Actions to take today to mitigate malicious cyber activity: Prioritize patching known exploited vulnerabilities in internet-facing systems. Review and ensure only necessary servers and services are exposed to the internet. Review platforms or services that have credentials listed in .env files for unauthorized access or use. SUMMARY The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory (CSA) to disseminate known indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) associated with threat actors deploying Androxgh0st malware. Multiple, ongoing investigations and trusted third party reporting yielded the IOCs and TTPs, and provided information on Androxgh0st malware’s ability to establish a botnet that can further identify and compromise vulnerable networks. The FBI and CISA encourage organizations to implement the recommendations in the Mitigations section of this CSA to reduce the likelihood and impact of cybersecurity incidents caused by Androxgh0st infections. Download the PDF version of this report: AA24-016A Known Indicators of Compromise Associated with Androxgh0st Malware (PDF, 576.40 KB ) AA24-016A Known Indicators of Compromise Associated with Androxgh0st Malware - Spanish (PDF, 353.45 KB ) For a downloadable copy of IOCs, see: AA24-016A STIX XML (XML, 45.81 KB ) AA24-016A STIX JSON (JSON, 39.87 KB ) TECHNICAL DETAILS Note: This advisory uses the MITRE ATT&CK ® for Enterprise framework, version 14. See the MITRE ATT&CK Tact

Indicatori CISA verificabili

43 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Copertura parziale: sono mostrati solo gli indicatori verificati e interpretabili. 1 allegati richiedono ancora verifica o un formato supportato.

Ultima verifica: 2026-09-26T06:31:12.973276+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
urlhttp://raw[.]githubusercontent[.]com/0x5a455553/MARIJUANA/master/MARIJUANA[.]php
urlhttps://pastebin[.]com/raw/zw0gAmpC
urlhttp://tangible-drink[.]surge[.]sh/configx[.]txt
domain-namedsn[.]ovh
urlhttp://main[.]dsn[.]ovh/dns/pwer
domain-nameasyncfox[.]xyz
urlhttp://download[.]asyncfox[.]xyz/download/xmrig[.]x86_64
urlhttps://chainventures[.]co[.]uk/[.]well-known/aas
urlhttps://mc[.]rockylinux[.]si/seoforce/triggers/files/evil[.]txt
urlhttp://45[.]95[.]147[.]236/tmp[.]x86_64
MD53fae93618edffe4331d18d8b8e6df693wpx.php.txt; configx.txt; wpx.php; output.183848776.txt
SHA-106641b9b3b5088c48c7660ad3bf160bc87a929fdwpx.php.txt; configx.txt; wpx.php; output.183848776.txt
SHA-256de1114a09cbab5ae9c1011ddd11719f15087cc29c8303da2e71d861b0594a1bawpx.php.txt; configx.txt; wpx.php; output.183848776.txt
SSDEEP384:l+14vwiKv3P5oLO5OTaKo9E7nC27ziK5v2UxvdrC1tvq0derfc7R4bTfawxlsM1:lC4wiqUeKoEe27zioxvs1tvurfc7R4XFwpx.php.txt; configx.txt; wpx.php; output.183848776.txt
MD5c1070aca9fcff4a32934e6c8aee4ea48pwer
SHA-17d1beb03c32db43f5edd4c28f3c905954e40dbd6pwer
SHA-256bb7070cbede294963328119d1145546c2e26709c5cea1d876d234b991682c0b7pwer
SSDEEP24:FlSW9h2pYRX/rbm3mGiNzuaC9zlvdomBnwSBTK9kZeW76aMjY7tm13Wou:fTWDiNiaC9zlGmBwUKVW7ngc7pwer
MD59039ae16e5aaa63d9ffe88dfaf0f5108xmrig.x86_64
SHA-159ce7486745b08d1adba49f2413133c441194986xmrig.x86_64
SHA-2566b5846f32d8009e6b54743d6f817f0c3519be6f370a0917bf455d3d114820bbcxmrig.x86_64
SSDEEP24576:0yX5ODpUkOVgBLzfGmvzow4DKBLkTzvXYSXyx6heKdtEZ8xyYMTsBGHfUbEW1hN5:30f5BvfL0w4DKfHg0MEuywQHsIsVe0xmrig.x86_64
MD5fe53c38f61588efd90af97185e315612vin.php
SHA-179d3143a47dc02768ff5fda8dbcf464c5cdf115bvin.php
SHA-256ca45a14d0e88e4aa408a6ac2ee3012bf9994b16b74e3c66b588c7eabaaec4d72vin.php
SSDEEP1536:OBmcCl2p0bH6R7PExxtJTlRkbSONu+rx/g:GbTR7PYTlRkbSONu+6vin.php
MD562a06bea8c6e276b5e532944cfc863e5
SHA-109bd9b17a64b20ba66582dbc3ce08169697177a8
SHA-25623fc51fde90d98daee27499a7ff94065f7ed4ac09c22867ebd9199e025dee066
SSDEEP98304:Zqx7CWlMSspXcj8yY0vV8yaKSVaxX5ZDAohuNSRW8maMa6uEPQGkfAo1qYY:4gWlM9P0vNhuazlGc1qY
MD56e793efe40e355643423f53de43952d3aas
SHA-1270e1c883b498eaff08550e823f5cac21bff54e5aas
SHA-256dcf8f640dd7cc27d2399cce96b1cf4b75e3b9f2dfdf19cee0a170e5a6d2ce6b6aas
SSDEEP96:1Aru6rUjc+Jji1x08MvDNX4waaxDUhoiZy:S66IjcJ1O8MrNXRaG4hoYyaas
MD51fb78440dc44b0900b27260a16d9771eevil.txt
SHA-1452ec481734a78597b928e29c834d0e43fb2c7e2evil.txt
SHA-25659e90be75e51c86b4b9b69dcede2cf815da5a79f7e05cac27c95ec35294151f4evil.txt
SSDEEP48:uGOx421MXw/T121uM+bdegRfgXPHqgKJOzggxz7gy:gx421MgL121uRdeufkPHqLsge7Levil.txt
ipv4-addr45[.]95[.]147[.]236
MD595f745a5db131b1ca34e44848fd52edbMARIJUANA[1].php
SHA-15fae94432540ade68eabce94140c9a5be153b3c8MARIJUANA[1].php
SHA-2560df17ad20bf796ed549c240856ac2bf9ceb19f21a8cae2dbd7d99369ecd317efMARIJUANA[1].php
SSDEEP384:LXeDZH3fyCT8gy3r+0JO07JaLb/J8o7Ck2JgWBBjrAvjfnWprAvHfAGCiWRo0/NX:LXeDZXfJbr3iRo0/NZDPWeMARIJUANA[1].php

Provenienza

Allegato ufficiale CISA · 2024-01-16T14:51:16Z

SHA-512: 2879e202a6f3f7a0b7c93fc3ce3acea58ef439dcd503fe9965581b48fd7191201a79c1a0976b352467addf3e49000ddbb0bc140b0f53b76d37291138f6044794

Fonte
CISA Cybersecurity Advisories
Entità pubblicatrice
CISA
Tipo entità
Autorità nazionale
Area
North America · US
Lingua originale
en · traduzione in preparazione
Pubblicazione
16/01/2024 13:00
Condivisione
TLP:CLEAR
MITRE ATT&CK
T1027, T1027.010, T1046, T1059.006, T1068, T1071.001, T1078, T1083, T1105, T1114, T1136, T1190, T1505, T1505.003, T1552.001, T1583.005, T1583.006, T1595, T1595.002
CVE
CVE-2017-9841, CVE-2018-15133, CVE-2021-41773
Classificazione
Critica
Paese indicato
US
Perimetro tecnico

Prodotti e versioni interessati

Verifica in corso
Informazione non ancora acquisita.

Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.

Azione indicata dalla fonte

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Riferimenti tecnici ufficiali

Apri la fonte originale